Chef de Projet Cybersécurité des Infrastructures - SPW Digital
Description
SPW Digital is looking for a confirmed project manager to lead infrastructure cybersecurity initiatives with a strong focus on Identity and Access Management. The mission covers IAM components across infrastructure, applications and cloud environments. The consultant will take projects from initial study and scoping through deployment and production. Delivery must remain aligned with business objectives, organizational constraints and regulatory requirements.
The IAM scope includes identity and account lifecycle management, automated provisioning and deprovisioning, roles and entitlements, least privilege and segregation of duties. It also covers identity federation, Single Sign-On, multi-factor and passwordless authentication, access reviews, certification, traceability and compliance reporting. Integration is expected with HR repositories, directories, applications, cloud environments and infrastructure services. Privileged, technical and non-human identities must be coordinated with PAM controls.
The project manager will coordinate infrastructure, network, cloud, security and supplier stakeholders while managing scope, objectives, planning, resources, budgets, deliverables, risks and governance reporting. The role also supports migrations, testing, validation, change and user adoption, and may extend to SASE, ZTNA, VPN, firewalls, secure networks and cloud security. Projects may include strategic studies, specifications, market consultations and operational security deployments. The assignment is full time and hybrid in Namur, with at least 60% on-site presence and more when required.
Top Reasons to Apply
Lead strategic IAM
End-to-end ownership
Complex security scope
Multidisciplinary collaboration
Cloud security exposure
Detailed Responsibilities and Skills
Additional Responsibilities
- Facilitate steering committees workshops
- Contribute infrastructure security projects
- Frame select IAM components
- Deploy production IAM components
- Manage identity account lifecycle
- Automate access provisioning deprovisioning
- Define roles access rights
- Implement least privilege controls
- Implement segregation duty controls
- Implement identity federation SSO
- Implement multifactor passwordless authentication
- Run access certification campaigns
- Ensure traceability compliance reporting
- Integrate IAM HR repositories
- Integrate directories applications cloud
- Coordinate privileged technical accounts
- Coordinate non-human identities PAM
- Migrate identities access rights
- Manage testing change adoption
- Deliver SASE ZTNA projects
- Deliver VPN firewall projects
- Deliver secure network projects
- Deliver cloud security projects
- Conduct strategic security studies
- Prepare specifications market consultations
- Deploy operational security solutions
- Collaborate infrastructure network teams
- Collaborate cloud security suppliers
- Facilitate decisions stakeholder arbitration
- Coordinate all project actors
- Support migration testing validation
- Support production deployment teams
- Contribute operational security activities
- Support other security themes
General skills
- Mandatory: T2 - Confirmed Business Project Manager profile.
- Mandatory: Recent, demonstrable implementation of an IAM solution in a complex environment.
- Mandatory: Ability to demonstrate the IAM role performed, results obtained, difficulties encountered and lessons learned.
- Mandatory: Full project responsibility covering budget, planning, risks, governance and reporting.
- Mandatory: Transform business and security needs into a feasible IAM roadmap.
- Mandatory: Manage technical and organizational dependencies.
- Mandatory: Lead the solution through adoption and operational use.
- Mandatory: T2 confirmed coordination capability.
- Mandatory: T2 confirmed project-management capability.
- Mandatory: T2 confirmed project-risk-management capability.
- Mandatory: Leadership and ability to unite multidisciplinary teams.
- Mandatory: Excellent written and oral communication.
- Mandatory: Strong organization and prioritization.
- Mandatory: Analytical and synthesis capability.
- Mandatory: Methodological rigor.
- Mandatory: Autonomy and proactivity.
- Mandatory: Diplomacy and ability to converge divergent interests.
- Mandatory: Ability to explain complex subjects to non-technical audiences.
- Mandatory: French at C2 proficiency level.
- Mandatory: Willingness to work on site at least 60% of the time, and more if necessary.
- Preferred: Experience delivering IAM in a large organization.
- Preferred: Experience delivering IAM in a hybrid environment.
- Preferred: T2 confirmed human change-management capability.
- Preferred: T1 junior supplier-management and public-procurement capability.
Technical skills
- Mandatory: T2 confirmed IAM, RBAC, Zero Trust, SSO and PAM capability.
- Mandatory: Identity and account lifecycle management for joiners, movers, role changes and leavers.
- Mandatory: Automated access provisioning and deprovisioning.
- Mandatory: Roles, entitlements, least privilege and segregation of duties.
- Mandatory: Identity federation, Single Sign-On, multifactor authentication and passwordless authentication.
- Mandatory: Access review and certification campaigns, traceability and compliance reporting.
- Mandatory: IAM integration with HR repositories, directories, applications, cloud and infrastructure services.
- Mandatory: Handling privileged accounts, technical accounts and non-human identities in coordination with PAM.
- Mandatory: Identity and entitlement migration, testing, change management and user adoption.
- Preferred: T1 junior cybersecurity knowledge covering NIS2 and ISO27001.
- Preferred: T2 confirmed PKI and HSM knowledge.
- Preferred: T2 confirmed networks, firewalls, VPN and SASE knowledge.
- Preferred: T2 confirmed cloud-security knowledge.
- Preferred: Complementary knowledge of PAM, PKI, HSM, SASE, networks, firewalls, VPN and cloud.
Tools
- Mandatory: IAM solution components.
- Mandatory: PAM-related controls for privileged and non-human identities.
- Preferred: PKI and HSM technologies.
- Preferred: SASE and ZTNA architectures.
- Preferred: VPN and firewall technologies.
- Preferred: Secure network technologies.
- Preferred: Cloud security environments.